CVE-2026-21295: Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21295?
CVE-2026-21295 is considered to have a high severity due to its potential to allow attackers to redirect users to untrusted sites.
How do I fix CVE-2026-21295?
To mitigate CVE-2026-21295, upgrade to Adobe Commerce versions 2.4.9-alpha4 or later, or apply relevant patches provided by Adobe.
What versions of Adobe Commerce are affected by CVE-2026-21295?
CVE-2026-21295 affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16, and earlier versions.
Can CVE-2026-21295 be exploited remotely?
Yes, CVE-2026-21295 can be exploited remotely, allowing attackers to redirect users to malicious sites.
What is the impact of CVE-2026-21295 on user security?
The impact of CVE-2026-21295 on user security includes potential phishing attacks and loss of trust in the affected application due to untrusted redirections.